I primarily use this solution for external security of our network.
System Administrator at a media company with 11-50 employees
Provides a high standard of security for our clients
Pros and Cons
- "We are a visual effects company, and there have been a number of high profile security issues in our industry. This has brought us to a higher standard of security, which our clients are very keen on these days."
- "We had a minor problem where there was a major system upgrade on the hardware platfrom and the Mac client was not available as soon as it might have been. The PC client was available immediately, but we had to wait a month or so, before there was a mac client. I was slightly irritated that it was not ready on time, but it was eventually resolved."
What is our primary use case?
How has it helped my organization?
We are a visual effects company, and there have been a number of high profile security issues in our industry. This has brought us to a higher standard of security, which our clients are very keen on these days.
What needs improvement?
We had a minor problem where there was a major system upgrade on the hardware platform and the Apple Mac client was not available as soon as it might have been. The PC client was available immediately, but we had to wait a month or so, before there was a Apple Mac client. I was slightly irritated that it was not ready on time, but it was eventually resolved.
For how long have I used the solution?
Almost two years.
Buyer's Guide
Fortinet FortiGate
February 2025

Learn what your peers think about Fortinet FortiGate. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
What do I think about the scalability of the solution?
Fortigate has more than adequate capability to cope with everything we require for the foreseeable future.
How are customer service and support?
The support is very good, and we have had no issues.
Which solution did I use previously and why did I switch?
Previously had a SonicWall. Even allowing for an upgrade discount on the SonicWall, the FortiGate was a more compelling purchase.
How was the initial setup?
It was fairly straightforward.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Mgr. IT Infrastructure and Network Operations at a media company with 11-50 employees
Centralized monitoring, policy management, and virtualized appliances allow us to take control over our public and private infrastructure
Pros and Cons
- "Centralized monitoring, policy management, and virtualized appliances allow us to take control over our public and private infrastructure."
- "Cisco Meraki products are rising very quickly in the cloud and the connected era. Meraki products offer much better ROI, upgradability, and manageability."
What is our primary use case?
- Security
- Monitoring and controlling
- VPN
- Active Directory integration
- Servers
- All components related to an enterprise environment.
How has it helped my organization?
We replaced Sophos with FortiGate and found it better than the Sophos product. It has better control, insights, and prevention from crypto malware and other threats.
What is most valuable?
The most valuable features are centralized monitoring, policy management, and virtualized appliances so we can have control over public and private Infrastructure.
What needs improvement?
Cisco Meraki products are rising very quickly in the cloud and the connected era. Meraki products are future proof and offer much better ROI, upgradability, and manageability.
IT is continuously evolving, and every few days or months, there is something new. Whoever evolves first will take the lead over the competition. Adopting and evolving is the key to success.
For how long have I used the solution?
Less than one year.
What do I think about the stability of the solution?
These products are solid and stable.
What do I think about the scalability of the solution?
We have not had any issues with scalability.
How are customer service and technical support?
Our experience with support has been fine. No trouble or hassle.
Which solution did I use previously and why did I switch?
Sophos: It was good for small businesses, who are evolving and improving. Though, I found Cisco Meraki to be much better.
How was the initial setup?
Part of the setup was straightforward and other parts were complex. They need to work on feature placements and menus.
What about the implementation team?
We did the implementation through a vendor, who had good experience.
What was our ROI?
Two to three years, depending on usage type, number of users, and organizational size.
Which other solutions did I evaluate?
Yes, we did, Palo Alto and other solutions, but we found FortiGate to be the best solution at that point in time.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Fortinet FortiGate
February 2025

Learn what your peers think about Fortinet FortiGate. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
ICT/Presales Manager at Balton Uganda
A reliable and practical solution that assists us in our day-to-day operations
Pros and Cons
- "Fortinet FortiGate's reliability is valuable."
- "I would like some automated custom reporting."
What is our primary use case?
We use Fortinet FortiGate for basic network security and people accessing through VPN.
How has it helped my organization?
Fortinet FortiGate is a reliable and practical solution that assists us in our day-to-day operations.
What is most valuable?
Fortinet FortiGate's reliability is valuable.
What needs improvement?
I would like some automated custom reporting.
For how long have I used the solution?
I have been using Fortinet FortiGate for one year.
What do I think about the stability of the solution?
Fortinet FortiGate is stable.
What do I think about the scalability of the solution?
The scalability has met our requirements. We have around 40 users.
Which solution did I use previously and why did I switch?
We previously used DrayTek before switching to Fortinet FortiGate which has more features.
What about the implementation team?
The implementation was completed in-house.
Which other solutions did I evaluate?
We evaluated Palo Alto Networks, but the cost of the solution and support were higher than Fortinet FortiGate.
What other advice do I have?
I give Fortinet FortiGate an eight out of ten.
The maintenance requires one person.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
System Administrator at a computer software company with 501-1,000 employees
Easy to configure and the technical support is good, but the newer versions have issues with stability
Pros and Cons
- "The most valuable feature is the ease of configuration."
- "One of the problems I was having was with user mapping, and it is an issue for which I have escalated tickets with Fortinet support."
What is our primary use case?
We use this firewall as part of our security solution.
What is most valuable?
The most valuable feature is the ease of configuration.
What needs improvement?
There are a lot of known issues in some newer versions of the FortiGate operating system, so there is room for improvement with that. One of the problems I was having was with user mapping, and it is an issue for which I have escalated tickets with Fortinet support.
Having the newer features work in the older, more stable versions of the product would be great. Some of the new features might really help a lot, but there are problems with stability.
For how long have I used the solution?
I have been working with FortiGate for approximately two years.
What do I think about the stability of the solution?
There are a lot of new features built into newer releases, but there are not very stable.
How are customer service and technical support?
The Fortinet technical support is awesome. They're handling my problem quickly and doing it well.
What's my experience with pricing, setup cost, and licensing?
The price is okay.
Which other solutions did I evaluate?
I have compared solutions from other vendors including Palo Alto.
What other advice do I have?
This is a good product, however, there is always room for improvement.
I would rate this solution a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
Consultant
Saved a bundle by not needing past appliances from an NGFW, however it needs better performance on bandwidth demands for smaller devices
Pros and Cons
- "Consolidated our network environment at all locations, but mainly at our datacenter."
- "One area for improvement is the performance on bandwidth demands for smaller devices, as well as better web filtering."
What is our primary use case?
Firewall/Web Filter management. We have over 30 sites, and it is imperative that one person (myself) can plan, implement, and deploy these devices to our sites and manage them when finished.
How has it helped my organization?
Consolidated our network environment at all locations, but mainly at our datacenter.
What is most valuable?
The web filtering was the most valuable, because at a school board, we need to make sure the students are not tying up our bandwidth and also to keep the bad guys out.
What needs improvement?
One area for improvement is the performance on bandwidth demands for smaller devices, as well as better web filtering. Each manufacturer has their own way of filtering and each one needs improvement in categories, URL, and/or application filtering.
For how long have I used the solution?
One to three years.
What was our ROI?
We saved a bundle by not needing all the past appliances from an NGFW.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Consultant at Webernetz.net - Network Security Consulting
Cisco ASA vs. Fortinet FortiGate vs. Palo Alto vs. Juniper SSG
Since IPv6 gets more and more important, I am using it by default on all my test firewalls, which of course support IPv6. However, when comparing the different functions and administration capabilities, they vary significantly.
Here comes my short evaluation of the IPv6 functions on the following four firewalls: Cisco ASA, Fortinet FortiGate, Juniper SSG, and Palo Alto.
Criteria
I was merely interested in the basic IPv6 usage and not in the typical firewall categories:
- Interface: IPv6 address and link-local address configurable?
- Router Advertisement and DHCPv6: Whether the firewalls support nothing (–), only RA (-), DHCPv6 relay (ο), stateless DHCPv6 (+), or stateful DHCPv6 (++). The existence of stateless DHCPv6 is vital for delivering the DNS server IPv6 addresses to the clients. (The “IPv6 Router Advertisement Options for DNS Configuration”, RFC 6106, is not supported by any of these devices.)
- Security Policy: Whether IPv4 and IPv6 addresses can be used in the same policy and whether address groups can have objects from both protocols.
- Administration: How easy are the IPv6 functions to manage? Only via the CLI (–), fifty-fifty (ο), GUI but complicated (+) , or fully via the GUI (++).
Results
These are the results. They range from — via ο to ++.
|
Cisco ASA
|
Fortinet FortiGate
|
Juniper ScreenOS
|
Palo Alto
|
Version
|
9.2(3)
|
5.2.2
|
6.3.0r18.0
|
6.1.3
|
Interface
|
++
|
+
|
++
|
++
|
RA, DHCPv6
|
-
|
++
|
+
|
0
|
Security Policy
|
++
|
-
|
-
|
++
|
Administration | + | - | + | ++ |
Details
Cisco ASA
The Cisco ASA has no DHCPv6 instance running. That is: there is no way to run an IPv6-only network because clients won’t get the DNS server. The security policy is capable of both protocols. Everything is configurable via the GUI, which is not the best at all.
Fortinet FortiGate
The FortiGate is the only firewall with a stateful DHCPv6 server. Great. However, two distinct security policies must be used and nothing of the IPv6 settings are configurable via the GUI. WHAT???
Juniper SSG (ScreenOS)
ScreenOS is dead. However, most of the IPv6 functions are working quite good, except the protocol dependent security policies. Everything is accessible via the GUI, but sometimes on confusing positions.
Palo Alto
Palo Alto did a good job on the IPv6 interfaces and security policies. The GUI is quite intuitive and the policy accepts both protocols at the same time. Unluckily, there is no DHCPv6 server which makes it impossible to operate an IPv6-only client network behind a Palo Alto (without further servers).
Conclusion
It’s interesting to see the differences between those firewalls. While the Fortinet und Juniper firewalls support the whole SLAAC process incl. DNS servers, they have no single security policy for both protocols and are horrable to configure.
The Palo Alto is quite good to configure but lacks the DHCPv6 server. Same for the Cisco.
In summary, all firewalls position in the middle of my scale. From an IPv6-only view, I cannot say which one is the best. It depends….
Originally published on blog.webernetz.net
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IP Senior Engineer at a comms service provider with 501-1,000 employees
It offers stability, scalability and plenty of security features. Enjoy fast and effective troubleshooting as everything is organized in a very understandable way.
What is most valuable?
- High Availability clustering
- SNAT/DNAT
- Policies section view
- Virtual Domains
- Logging and Reporting
- IPS
How has it helped my organization?
It has made our daily operations easier, as well as adding security, and stability to them. Adding or removing security policies is simplified through its web interface, or CLI. Additionally, troubleshooting is fast and effective, as everything is organized in a very understandable way.
What needs improvement?
Its web interface needs to be more stable, and more functional, through the variety of browsers. Additionally a nice add-on would be a “diagnostic sniffer” capability in the web interface.
For how long have I used the solution?
I've used it for six years.
What was my experience with deployment of the solution?
With different browsers, the web interface crashes. On newer versions of Fortios the problem has been minimized.
What do I think about the stability of the solution?
Not at all, it is as stable as it should be.
What do I think about the scalability of the solution?
I believe that it is a little complex adding new firewalls in an existing cluster.
How are customer service and technical support?
Customer Service:
8/10.
Technical Support:9/10.
Which solution did I use previously and why did I switch?
We are using different firewall solutions, in parallel with the Fortigate ones.
How was the initial setup?
It was straightforward. Taking control of the device for first time is easy, and the cookbook manual is very helpful.
What about the implementation team?
A vendor team offered five day training but the implementation was in-house.
Which other solutions did I evaluate?
We evaluated other solutions, but I was not responsible for taking the final decision.
What other advice do I have?
Throughout the last six years we have been using Fortigate firewalls, and the experience we gained is only positive. These devices are easy to manage, operate and troubleshoot any issues that might rise. The use of virtual domains has added more security presence by only having one physical device, and it’s easy to create them. Also, by enabling other security features on the VDoms, the physical performance will not be affected.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Telecommunications Engineer at a university with 1,001-5,000 employees
Good network protection and configuration that is easy to set up and quick to deploy
Pros and Cons
- "The most valuable features are the policies, filtering, and configuration."
- "Technical support is good but the response time could be faster."
What is our primary use case?
We are using this solution to protect our network on every site. We are using it as a Network Firewall.
What is most valuable?
The most valuable features are the policies, filtering, and configuration.
What needs improvement?
Technical support is good but the response time could be faster.
When it's overloaded, it works slower and overheats.
The data analysis could be improved.
For how long have I used the solution?
I have been using Fortinet FortiGate for 15 years.
We are using the 100 models.
What do I think about the stability of the solution?
This solution is pretty stable.
What do I think about the scalability of the solution?
It's a scalable solution. I would rate it a seven out of ten.
We have 2,500 users in our organization.
How are customer service and technical support?
Technical support is good. I would rate them an eight out of ten.
Which solution did I use previously and why did I switch?
We have also used Huawei.
How was the initial setup?
The initial setup is straightforward. It's pretty easy.
At the very most, it takes a day to deploy.
What other advice do I have?
Before deciding to install this solution, be sure to conduct an analysis of your environment. You may need a larger one or this may be too big for their needs.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Fortinet FortiGate Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2025
Popular Comparisons
Netgate pfSense
OPNsense
Cisco Secure Firewall
Sophos XG
Palo Alto Networks NG Firewalls
Check Point NGFW
Azure Firewall
WatchGuard Firebox
SonicWall TZ
Juniper SRX Series Firewall
SonicWall NSa
Fortinet FortiGate-VM
Untangle NG Firewall
Sophos XGS
Fortinet FortiOS
Buyer's Guide
Download our free Fortinet FortiGate Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Comparison of Barracuda F800, SonicWall 5600 and Fortinet
- Sophos XG 210 vs Fortigate FG 100E
- Looking Into Implementing a Web Security Solution.
- Cyberoam or Fortinet?
- Fortinet, Palo Alto or Check Point?
- Which would you recommend to your boss, Fortinet FortiGate or Sophos UTM?
- What Is The Biggest Difference Between Cisco ASA And Fortinet FortiGate?
- Cisco Firepower vs. FortiGate
- We're trying to choose between Fortinet or Checkpoint UTM firewalls. Can you help?
- What Is The Biggest Difference Between Fortinet FortiGate and Meraki MX Firewalls?